Potentially Suspicious Office Document Executed From Trusted Location

 Original Source: [Sigma source]
Title: Potentially Suspicious Office Document Executed From Trusted Location
Status: test
Description:Detects the execution of an Office application that points to a document that is located in a trusted location. Attackers often used this to avoid macro security and execute their malicious code.
References:
  -Internal Research
  -https://twitter.com/Max_Mal_/status/1633863678909874176
  -https://techcommunity.microsoft.com/t5/microsoft-365-blog/new-security-hardening-policies-for-trusted-documents/ba-p/3023465
  -https://twitter.com/_JohnHammond/status/1588155401752788994
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2023-06-21
modified:2023-10-18
Tags:
  • -'attack.stealth'
  • -'attack.t1202'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_parent:
    ParentImage|endswith:
      -'\explorer.exe'
      -'\dopus.exe'

  selection_img:
    - Image|endswith:
      - '\EXCEL.EXE'
      - '\POWERPNT.EXE'
      - '\WINWORD.exe'
    - OriginalFileName:
      - 'Excel.exe'
      - 'POWERPNT.EXE'
      - 'WinWord.exe'
  selection_trusted_location:
    CommandLine|contains:
      -'\AppData\Roaming\Microsoft\Templates'
      -'\AppData\Roaming\Microsoft\Word\Startup\'
      -'\Microsoft Office\root\Templates\'
      -'\Microsoft Office\Templates\'

  filter_main_dotx:
    CommandLine|endswith:
      -'.dotx'
      -'.xltx'
      -'.potx'

  condition:all of selection_* and not 1 of filter_main_*
Falsepositives:
  -Unknown
Level: high